MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb1286c7e69a05a86fa35f96444e808a7f9ed2ae3955918f5833d54b5657e290. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: eb1286c7e69a05a86fa35f96444e808a7f9ed2ae3955918f5833d54b5657e290
SHA3-384 hash: 07212fef62860faf32c84a2a8431d1ebb8ed0a00ada7ef7db15d98fc714d6d3d0d19257724c15fa355e50fa60b84ffb8
SHA1 hash: 08c7c9fc725e7788dbc9fa0c0f95103433017b9b
MD5 hash: b082beb9cabb02240b7841ac800d4a77
humanhash: jersey-angel-violet-massachusetts
File name:all.sh
Download: download sample
File size:771 bytes
First seen:2026-01-22 20:35:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ZDkH/FboCvHFmCvHFpCvHFWlCdFk3CtFM5gFwCslCdFW3CtFMDgFwCUeD:hOFbbvnvqvhES5F2SHU6
TLSH T14201F580257013707CA698EA4AB20D3D34C5905D3E975FF87F66B0CA24C7C24F0A62A9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://144.172.115.193/huhu/titanjr.n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-21T15:32:00Z UTC
Last seen:
2026-01-23T12:54:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=42e84d9d-1900-0000-19cf-afe7a60b0000 pid=2982 /usr/bin/sudo guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986 /tmp/sample.bin guuid=42e84d9d-1900-0000-19cf-afe7a60b0000 pid=2982->guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986 execve guuid=7e4e869f-1900-0000-19cf-afe7ad0b0000 pid=2989 /usr/bin/wget net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=7e4e869f-1900-0000-19cf-afe7ad0b0000 pid=2989 execve guuid=45071eb3-1900-0000-19cf-afe7de0b0000 pid=3038 /usr/bin/curl guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=45071eb3-1900-0000-19cf-afe7de0b0000 pid=3038 execve guuid=d53164b7-1900-0000-19cf-afe7ea0b0000 pid=3050 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=d53164b7-1900-0000-19cf-afe7ea0b0000 pid=3050 execve guuid=eef32fc7-1900-0000-19cf-afe7160c0000 pid=3094 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=eef32fc7-1900-0000-19cf-afe7160c0000 pid=3094 execve guuid=a69cca0e-1a00-0000-19cf-afe78f0c0000 pid=3215 /usr/bin/busybox guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=a69cca0e-1a00-0000-19cf-afe78f0c0000 pid=3215 execve guuid=9879940f-1a00-0000-19cf-afe7900c0000 pid=3216 /usr/bin/busybox send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=9879940f-1a00-0000-19cf-afe7900c0000 pid=3216 execve guuid=7d3d8e12-1d00-0000-19cf-afe7f0130000 pid=5104 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=7d3d8e12-1d00-0000-19cf-afe7f0130000 pid=5104 clone guuid=6bb2c212-1d00-0000-19cf-afe7f2130000 pid=5106 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=6bb2c212-1d00-0000-19cf-afe7f2130000 pid=5106 clone guuid=72a0f012-1d00-0000-19cf-afe7f3130000 pid=5107 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=72a0f012-1d00-0000-19cf-afe7f3130000 pid=5107 clone guuid=3c320513-1d00-0000-19cf-afe7f4130000 pid=5108 /usr/bin/chmod guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=3c320513-1d00-0000-19cf-afe7f4130000 pid=5108 execve guuid=1b205e13-1d00-0000-19cf-afe7f6130000 pid=5110 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=1b205e13-1d00-0000-19cf-afe7f6130000 pid=5110 clone guuid=b1dcec14-1d00-0000-19cf-afe7fc130000 pid=5116 /usr/bin/wget net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=b1dcec14-1d00-0000-19cf-afe7fc130000 pid=5116 execve guuid=25857b26-1d00-0000-19cf-afe739140000 pid=5177 /usr/bin/curl guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=25857b26-1d00-0000-19cf-afe739140000 pid=5177 execve guuid=f16a7f2a-1d00-0000-19cf-afe755140000 pid=5205 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=f16a7f2a-1d00-0000-19cf-afe755140000 pid=5205 execve guuid=2232673a-1d00-0000-19cf-afe76b140000 pid=5227 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=2232673a-1d00-0000-19cf-afe76b140000 pid=5227 execve guuid=00cdab81-1d00-0000-19cf-afe777140000 pid=5239 /usr/bin/busybox guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=00cdab81-1d00-0000-19cf-afe777140000 pid=5239 execve guuid=62592d82-1d00-0000-19cf-afe778140000 pid=5240 /usr/bin/busybox send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=62592d82-1d00-0000-19cf-afe778140000 pid=5240 execve guuid=e0e52b85-2000-0000-19cf-afe7a0140000 pid=5280 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=e0e52b85-2000-0000-19cf-afe7a0140000 pid=5280 clone guuid=d4846385-2000-0000-19cf-afe7a1140000 pid=5281 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=d4846385-2000-0000-19cf-afe7a1140000 pid=5281 clone guuid=8c609e85-2000-0000-19cf-afe7a2140000 pid=5282 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=8c609e85-2000-0000-19cf-afe7a2140000 pid=5282 clone guuid=0bc2ca85-2000-0000-19cf-afe7a3140000 pid=5283 /usr/bin/chmod guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=0bc2ca85-2000-0000-19cf-afe7a3140000 pid=5283 execve guuid=fcb35a86-2000-0000-19cf-afe7a4140000 pid=5284 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=fcb35a86-2000-0000-19cf-afe7a4140000 pid=5284 clone guuid=8ecd7987-2000-0000-19cf-afe7a6140000 pid=5286 /usr/bin/wget net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=8ecd7987-2000-0000-19cf-afe7a6140000 pid=5286 execve guuid=d97cef98-2000-0000-19cf-afe7a7140000 pid=5287 /usr/bin/curl guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=d97cef98-2000-0000-19cf-afe7a7140000 pid=5287 execve guuid=018dfd9b-2000-0000-19cf-afe7a8140000 pid=5288 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=018dfd9b-2000-0000-19cf-afe7a8140000 pid=5288 execve guuid=261b1bac-2000-0000-19cf-afe7a9140000 pid=5289 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=261b1bac-2000-0000-19cf-afe7a9140000 pid=5289 execve guuid=31c839f5-2000-0000-19cf-afe7aa140000 pid=5290 /usr/bin/busybox guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=31c839f5-2000-0000-19cf-afe7aa140000 pid=5290 execve guuid=991e15f6-2000-0000-19cf-afe7ab140000 pid=5291 /usr/bin/busybox send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=991e15f6-2000-0000-19cf-afe7ab140000 pid=5291 execve guuid=161fbff9-2300-0000-19cf-afe7ac140000 pid=5292 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=161fbff9-2300-0000-19cf-afe7ac140000 pid=5292 clone guuid=499efbf9-2300-0000-19cf-afe7ad140000 pid=5293 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=499efbf9-2300-0000-19cf-afe7ad140000 pid=5293 clone guuid=ebb734fa-2300-0000-19cf-afe7ae140000 pid=5294 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=ebb734fa-2300-0000-19cf-afe7ae140000 pid=5294 clone guuid=082561fa-2300-0000-19cf-afe7af140000 pid=5295 /usr/bin/chmod guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=082561fa-2300-0000-19cf-afe7af140000 pid=5295 execve guuid=6471e0fa-2300-0000-19cf-afe7b0140000 pid=5296 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=6471e0fa-2300-0000-19cf-afe7b0140000 pid=5296 clone guuid=2bdc38fc-2300-0000-19cf-afe7b2140000 pid=5298 /usr/bin/wget net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=2bdc38fc-2300-0000-19cf-afe7b2140000 pid=5298 execve guuid=4c17c40d-2400-0000-19cf-afe7b3140000 pid=5299 /usr/bin/curl guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=4c17c40d-2400-0000-19cf-afe7b3140000 pid=5299 execve guuid=2a789710-2400-0000-19cf-afe7b4140000 pid=5300 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=2a789710-2400-0000-19cf-afe7b4140000 pid=5300 execve guuid=0ff5ab20-2400-0000-19cf-afe7b5140000 pid=5301 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=0ff5ab20-2400-0000-19cf-afe7b5140000 pid=5301 execve guuid=27acbf69-2400-0000-19cf-afe7b6140000 pid=5302 /usr/bin/busybox guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=27acbf69-2400-0000-19cf-afe7b6140000 pid=5302 execve guuid=2e91ab6a-2400-0000-19cf-afe7b7140000 pid=5303 /usr/bin/busybox send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=2e91ab6a-2400-0000-19cf-afe7b7140000 pid=5303 execve guuid=67092a6e-2700-0000-19cf-afe7b8140000 pid=5304 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=67092a6e-2700-0000-19cf-afe7b8140000 pid=5304 clone guuid=7c99576e-2700-0000-19cf-afe7b9140000 pid=5305 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=7c99576e-2700-0000-19cf-afe7b9140000 pid=5305 clone guuid=14f28e6e-2700-0000-19cf-afe7ba140000 pid=5306 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=14f28e6e-2700-0000-19cf-afe7ba140000 pid=5306 clone guuid=7c73c06e-2700-0000-19cf-afe7bb140000 pid=5307 /usr/bin/chmod guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=7c73c06e-2700-0000-19cf-afe7bb140000 pid=5307 execve guuid=189bca8c-2700-0000-19cf-afe7be140000 pid=5310 /usr/bin/bash guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=189bca8c-2700-0000-19cf-afe7be140000 pid=5310 clone guuid=8020648d-2700-0000-19cf-afe7c0140000 pid=5312 /usr/bin/wget net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=8020648d-2700-0000-19cf-afe7c0140000 pid=5312 execve guuid=6eece39d-2700-0000-19cf-afe7c9140000 pid=5321 /usr/bin/curl guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=6eece39d-2700-0000-19cf-afe7c9140000 pid=5321 execve guuid=1fb6fd9f-2700-0000-19cf-afe7ca140000 pid=5322 /usr/bin/busybox net send-data guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=1fb6fd9f-2700-0000-19cf-afe7ca140000 pid=5322 execve guuid=8ea4eaaf-2700-0000-19cf-afe7cb140000 pid=5323 /usr/bin/busybox net guuid=1f040b9f-1900-0000-19cf-afe7aa0b0000 pid=2986->guuid=8ea4eaaf-2700-0000-19cf-afe7cb140000 pid=5323 execve 4c579635-7e1c-59ca-8b5c-f1f6c28cf416 144.172.115.193:80 guuid=7e4e869f-1900-0000-19cf-afe7ad0b0000 pid=2989->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 149B guuid=d53164b7-1900-0000-19cf-afe7ea0b0000 pid=3050->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 97B f3d5390a-4e6e-5b56-b92e-72ea6a9a9627 144.172.115.193:21 guuid=eef32fc7-1900-0000-19cf-afe7160c0000 pid=3094->f3d5390a-4e6e-5b56-b92e-72ea6a9a9627 send: 74B aad5b54e-33ee-5f90-96f3-3ce440755e0b 144.172.115.193:64462 guuid=eef32fc7-1900-0000-19cf-afe7160c0000 pid=3094->aad5b54e-33ee-5f90-96f3-3ce440755e0b con fcc2183f-49fc-50ad-90a8-212095ebfb34 144.172.115.193:69 guuid=9879940f-1a00-0000-19cf-afe7900c0000 pid=3216->fcc2183f-49fc-50ad-90a8-212095ebfb34 send: 372B guuid=b1dcec14-1d00-0000-19cf-afe7fc130000 pid=5116->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 147B guuid=f16a7f2a-1d00-0000-19cf-afe755140000 pid=5205->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 95B guuid=2232673a-1d00-0000-19cf-afe76b140000 pid=5227->f3d5390a-4e6e-5b56-b92e-72ea6a9a9627 send: 74B 322cb66f-9691-5476-ad31-5852943476ea 144.172.115.193:34124 guuid=2232673a-1d00-0000-19cf-afe76b140000 pid=5227->322cb66f-9691-5476-ad31-5852943476ea con guuid=62592d82-1d00-0000-19cf-afe778140000 pid=5240->fcc2183f-49fc-50ad-90a8-212095ebfb34 send: 348B guuid=8ecd7987-2000-0000-19cf-afe7a6140000 pid=5286->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 147B guuid=018dfd9b-2000-0000-19cf-afe7a8140000 pid=5288->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 95B guuid=261b1bac-2000-0000-19cf-afe7a9140000 pid=5289->f3d5390a-4e6e-5b56-b92e-72ea6a9a9627 send: 74B 5da857a3-f394-5607-8edb-d496eaea438f 144.172.115.193:45238 guuid=261b1bac-2000-0000-19cf-afe7a9140000 pid=5289->5da857a3-f394-5607-8edb-d496eaea438f con guuid=991e15f6-2000-0000-19cf-afe7ab140000 pid=5291->fcc2183f-49fc-50ad-90a8-212095ebfb34 send: 348B guuid=2bdc38fc-2300-0000-19cf-afe7b2140000 pid=5298->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 146B guuid=2a789710-2400-0000-19cf-afe7b4140000 pid=5300->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 94B guuid=0ff5ab20-2400-0000-19cf-afe7b5140000 pid=5301->f3d5390a-4e6e-5b56-b92e-72ea6a9a9627 send: 74B 365db668-86b5-5a4b-8eb4-05e9b0739065 144.172.115.193:38517 guuid=0ff5ab20-2400-0000-19cf-afe7b5140000 pid=5301->365db668-86b5-5a4b-8eb4-05e9b0739065 con guuid=2e91ab6a-2400-0000-19cf-afe7b7140000 pid=5303->fcc2183f-49fc-50ad-90a8-212095ebfb34 send: 336B guuid=8020648d-2700-0000-19cf-afe7c0140000 pid=5312->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 147B guuid=1fb6fd9f-2700-0000-19cf-afe7ca140000 pid=5322->4c579635-7e1c-59ca-8b5c-f1f6c28cf416 send: 95B guuid=8ea4eaaf-2700-0000-19cf-afe7cb140000 pid=5323->f3d5390a-4e6e-5b56-b92e-72ea6a9a9627 con
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-01-22 20:36:46 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh eb1286c7e69a05a86fa35f96444e808a7f9ed2ae3955918f5833d54b5657e290

(this sample)

  
Delivery method
Distributed via web download

Comments